The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 30, 2022

Filed:

May. 05, 2020
Applicant:

Amazon Technologies, Inc., Seattle, WA (US);

Inventors:

Sarath Geethakumar, Bellevue, WA (US);

Krutarth Mukesh Gathani, Redmond, WA (US);

Bruce Cooper, North Perth, AU;

Eric Crahen, Seattle, WA (US);

Assignee:

AMAZON TECHNOLOGIES, INC., Seattle, WA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/32 (2006.01); H04L 9/08 (2006.01); H04L 9/14 (2006.01);
U.S. Cl.
CPC ...
H04L 9/3273 (2013.01); H04L 9/0819 (2013.01); H04L 9/0866 (2013.01); H04L 9/0894 (2013.01); H04L 9/14 (2013.01); H04L 9/3231 (2013.01); H04L 9/3247 (2013.01); H04L 9/3297 (2013.01);
Abstract

During provisioning of a biometric device, a hardware root of trust is established between the biometric device and a server. The biometric device includes a cryptographic processor with a first encryption key stored in secure storage. The first encryption key is used to establish a mutually authenticated communication channel with the server. A set of additional encryption keys between the device and the server are established via the communication channel. Biometric data generated by the biometric device is encrypted using the additional keys and digitally signed. The server receives the encrypted and signed data via the communication channel and verifies the signature. Once the signature is verified, the biometric data is then decrypted. The server then processes the decrypted biometric data. Data that does not arrive via the communication channel, that fails the verification, or that fails decryption is deleted or disregarded.


Find Patent Forward Citations

Loading…